PT-2001-2466 · Webstore · Webstore

Published

2001-06-12

·

Updated

2017-12-19

·

CVE-2001-1343

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions WebStore versions 4.14
Description The issue allows remote authenticated WebStore administrators to execute arbitrary code via shell metacharacters in the kill parameter of the ws mail.cgi script.
Recommendations For version 4.14, avoid using the kill parameter in the ws mail.cgi script until a patch is available. As a temporary workaround, consider restricting access to the ws mail.cgi script to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-1343

Affected Products

Webstore